View Full Version : My Forum got hacked, what do I do?
Spoolin
03-19-2009, 12:33 PM
Somebody, hacked into my Admin account, and banned my ip, so I cannot even log in. I am positive it is a particular person I banned from the forum because he warned me he was going to do it. I don't know how he did it because I changed my password multiple times, and there is no other admin account to hack other than mine. I tried to get into my Admin CP but I can't even do that now because they changed my password on me. What can I do? This is upsetting because I spent so much time getting that forum up. :(
snakes1100
03-19-2009, 12:44 PM
<a href="http://www.vbulletin.com/forum/showthread.php?t=255395" target="_blank">http://www.vbulletin.com/forum/showthread.php?t=255395</a>
Spoolin
03-19-2009, 12:54 PM
I can't even get as far as the log in box. It seems he has banned my ip address...
You have been banned for the following reason:
No reason was specified.
Date the ban will be lifted: Never
Marco van Herwaarden
03-19-2009, 01:03 PM
If you have lost your access information for your Admin account and can not reset the password using normal procedures, then please do the following:
- Register a new regular forum account.
- Upload tools.php from the 'do_not_upload' folder of your vBulletin distribution to your admincp directory.
- Now point your browser to tools.php.
- Choose "[Reset Admin Access]" to promote the new user account to admin
- Once your problem is fixed please remove tools.php again from the server.
- Optional: If needed add the userid of the new user to the super administrator list in your config.php
Spoolin
03-19-2009, 01:21 PM
Marco, is there a way I can create a new username without having to go to the forum url, because as soon as I try to go to the forum page I get the message that says I am banned. I cannot even register a new account or anything.
After I do get this sorted out, how can I prevent this from happenening again? It's like he gained access to my IP address because I don't know how else he could have gotten into my account and done all of this.
mcrider
03-19-2009, 01:25 PM
Clear your cookies, then try creating another account.
nexialys
03-19-2009, 01:31 PM
ask your best friend, or change to a different computer with a different web access...
mcrider
03-19-2009, 01:36 PM
If your IP was banned doesn't the message say that your IP was banned???
Spoolin
03-19-2009, 06:04 PM
Tried deleting my cookies. Still get the message. :(
You have been banned for the following reason:
No reason was specified.
Date the ban will be lifted: Never
puertoblack2003
03-19-2009, 06:36 PM
Tried deleting my cookies. Still get the message. :(
then go to another computer or a friends house or something and follow marco intro that is the only way brotha.And rename your your file to where the the forum is housed to avoid any other damage to your board and they can't log in...
Spoolin
03-19-2009, 11:09 PM
I was able to give admin access to a friend. He said there are no ip's banned or emails but I still get the banned message along with a lot of other users. How else could have banned my account?
snakes1100
03-19-2009, 11:11 PM
Use tools.php and rebuild the caches listed.
Spoolin
03-19-2009, 11:23 PM
Just tried that as recommended.
Still banned. :(
mcrider
03-19-2009, 11:36 PM
Did your friend log in with your "banned" account?
Spoolin
03-19-2009, 11:38 PM
Nope, I gave his username admin permissions through the tools.php.
I'm really stumped here.
mcrider
03-19-2009, 11:44 PM
Have you checked to make sure the usergroup or groups that the banned users are in haven't been changed to a banned group.
Edit: But that still doesn't explain why you can create another account....hmmmm
Spoolin
03-20-2009, 12:27 AM
I'm in! "This Usergroup is not a 'Banned' Group" for the " Unregistered/Not logged in usergroup " was set to NO
Angel-Wings
03-20-2009, 08:15 AM
Edit: But that still doesn't explain why you can create another account....hmmmm
Because if a user is banned the IP is banned too so if there's a static IP, the message about "You've been banned" will appear even when trying to register again.
For that particular problem - use direct SQL access and change the usergroup of your own account back to "Admin" and the Email address if this was changed.
Then go through the password recovery process to get access again.
And then - reinstall everything that it doesn't happen again
mcrider
03-20-2009, 10:46 AM
Because if a user is banned the IP is banned too so if there's a static IP, the message about "You've been banned" will appear even when trying to register again.
User ban and IP ban are to separate type of banning options.
To ban an IP you have to manually ban an IP under "User Banning Options" > "Ban IP Addresses"
The reason he couldn't create another user was because the " Unregistered/Not logged in usergroup " was set as a banned group, which makes sense now.....;)
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.